diff --git a/qdrant-landing/content/blog/cve-2024-2221-response.md b/qdrant-landing/content/blog/cve-2024-2221-response.md index 203ffc03a..2c26e8340 100644 --- a/qdrant-landing/content/blog/cve-2024-2221-response.md +++ b/qdrant-landing/content/blog/cve-2024-2221-response.md @@ -3,7 +3,7 @@ title: "Response to CVE-2024-2221: Arbitrary file upload vulnerability" draft: false slug: cve-2024-2221-response short_description: Qdrant keeps your systems secure -description: Upgrade your deployments to at least v1.8.0. Cloud deployments not materially affected. +description: Upgrade your deployments to at least v1.9.0. Cloud deployments not materially affected. preview_image: /blog/cve-2024-2221/cve-2024-2221-response-social-preview.png # social_preview_image: /blog/Article-Image.png # Optional image used for link previews @@ -22,7 +22,7 @@ weight: 0 # Change this weight to change order of posts ### Summary A security vulnerability has been discovered in Qdrant affecting all versions -prior to v1.8, described in [CVE-2024-2221](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-2221). +prior to v1.9, described in [CVE-2024-2221](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-2221). The vulnerability allows an attacker to upload arbitrary files to the filesystem, which can be used to gain remote code execution. @@ -31,13 +31,13 @@ filesystem is read-only and authentication is enabled by default. At worst, the vulnerability could be used by an authenticated user to crash a cluster, which is already possible, such as by uploading more vectors than can fit in RAM. -Qdrant has addressed the vulnerability in v1.8.3 and above with code that +Qdrant has addressed the vulnerability in v1.9.0 and above with code that restricts file uploads to a folder dedicated to that purpose. ### Action Check the current version of your Qdrant deployment. Upgrade if your deployment -is not at least v1.8.3. +is not at least v1.9.0. To confirm the version of your Qdrant deployment in the cloud or on your local or cloud system, run an API GET call, as described in the [Qdrant Quickstart @@ -58,8 +58,10 @@ guide. The default commands automatically pull the latest version of Qdrant. If you’ve set up Qdrant on kubernetes using a helm chart, follow the README in the [qdrant-helm](https://github.com/qdrant/qdrant-helm/tree/main?tab=readme-ov-file#upgrading) repository. -Make sure applicable configuration files point to version v1.8.3 or above. +Make sure applicable configuration files point to version v1.9.0 or above. #### If you use the Qdrant cloud No action is required. This vulnerability does not materially affect you. However, we suggest that you upgrade your cloud deployment to the latest version. + +> Note: This article has been updated on 2024-05-10 to encourage users to upgrade to 1.9.0 to ensure protection from both CVE-2024-2221 and CVE-2024-3829. diff --git a/qdrant-landing/content/blog/cve-2024-3829-response.md b/qdrant-landing/content/blog/cve-2024-3829-response.md new file mode 100644 index 000000000..fd66ee12d --- /dev/null +++ b/qdrant-landing/content/blog/cve-2024-3829-response.md @@ -0,0 +1,65 @@ +--- +title: "Response to CVE-2024-3829: Arbitrary file upload vulnerability" +draft: false +slug: cve-2024-3829-response +short_description: Qdrant keeps your systems secure +description: Upgrade your deployments to at least v1.9.0. Cloud deployments not materially affected. +preview_image: /blog/cve-2024-3829-response/cve-2024-3829-response-social-preview.png + +# social_preview_image: /blog/Article-Image.png # Optional image used for link previews +# title_preview_image: /blog/Article-Image.png # Optional image used for blog post title +# small_preview_image: /blog/Article-Image.png # Optional image used for small preview in the list of blog posts +date: 2024-06-10T17:00:00Z +author: Mac Chaffee +featured: false +tags: + - cve + - security +weight: 0 # Change this weight to change order of posts +# For more guidance, see https://github.com/qdrant/landing_page?tab=readme-ov-file#blog +--- + +### Summary + +A security vulnerability has been discovered in Qdrant affecting all versions +prior to v1.9, described in [CVE-2024-3829](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-3829). +The vulnerability allows an attacker to upload arbitrary files to the +filesystem, which can be used to gain remote code execution. This is a different but similar vulnerability to CVE-2024-2221, announced in April 2024. + +The vulnerability does not materially affect Qdrant cloud deployments, as that +filesystem is read-only and authentication is enabled by default. At worst, +the vulnerability could be used by an authenticated user to crash a cluster, +which is already possible, such as by uploading more vectors than can fit in RAM. + +Qdrant has addressed the vulnerability in v1.9.0 and above with code that +restricts file uploads to a folder dedicated to that purpose. + +### Action + +Check the current version of your Qdrant deployment. Upgrade if your deployment +is not at least v1.9.0. + +To confirm the version of your Qdrant deployment in the cloud or on your local +or cloud system, run an API GET call, as described in the [Qdrant Quickstart +guide](https://qdrant.tech/documentation/cloud/quickstart-cloud/#step-2-test-cluster-access). +If your Qdrant deployment is local, you do not need an API key. + +Your next step depends on how you installed Qdrant. For details, read the +[Qdrant Installation](https://qdrant.tech/documentation/guides/installation/) +guide. + +#### If you use the Qdrant container or binary + +Upgrade your deployment. Run the commands in the applicable section of the +[Qdrant Installation](https://qdrant.tech/documentation/guides/installation/) +guide. The default commands automatically pull the latest version of Qdrant. + +#### If you use the Qdrant helm chart + +If you’ve set up Qdrant on kubernetes using a helm chart, follow the README in +the [qdrant-helm](https://github.com/qdrant/qdrant-helm/tree/main?tab=readme-ov-file#upgrading) repository. +Make sure applicable configuration files point to version v1.9.0 or above. + +#### If you use the Qdrant cloud + +No action is required. This vulnerability does not materially affect you. However, we suggest that you upgrade your cloud deployment to the latest version. diff --git a/qdrant-landing/static/blog/cve-2024-3829-response/cve-2024-3829-response-social-preview.png b/qdrant-landing/static/blog/cve-2024-3829-response/cve-2024-3829-response-social-preview.png new file mode 100644 index 000000000..fcf629836 Binary files /dev/null and b/qdrant-landing/static/blog/cve-2024-3829-response/cve-2024-3829-response-social-preview.png differ